5
CVSSv2

CVE-2007-0463

Published: 29/01/2007 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote malicious users to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.

Vulnerable Product Search on Vulmon Subscribe to Product

apple software update 2.0.5

Exploits

source: wwwsecurityfocuscom/bid/22222/info Apple Software Update is prone to a format-string vulnerability This issue presents itself because the application fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function A successful attack may crash the application or possibl ...